This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] HJT Posts and Registry Help

22 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hello to all at what the tech, i used to visit when it was Tom Coyote, and they did a fantastic job helping out. I am writing because I'd like to "tune-up" my computer again. I have Windows XP, service pack 3, Intel Celeron, 2.6 GHz, 2 GB RAM. Recently it has been crashing when trying to view certain video formats, mp4 in particular, or trying to use the "view full screen" feature. I think there must be some registry errors, but what do I know? I appreciate your help and am ready to see this thru to the end. Please let me know where to begin, I know y'all prefer we do not use MalwareBytes, HijackThis, or other programs without proper consultation first, as any tool could cause more damage than good in the wrong hands. I look forward to your response. Juliusmaximus
Hi,

Please do the following:



Download OTL to your Desktop
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Check the boxes beside LOP Check and Purity Check.
  • Under the Custom Scan box paste this in


    netsvcs
    %SYSTEMDRIVE%\*.exe
    /md5start
    eventlog.dll
    scecli.dll
    netlogon.dll
    cngaudit.dll
    sceclt.dll
    ntelogon.dll
    logevent.dll
    iaStor.sys
    nvstor.sys
    atapi.sys
    IdeChnDr.sys
    viasraid.sys
    AGP440.sys
    vaxscsi.sys
    nvatabus.sys
    viamraid.sys
    nvata.sys
    nvgts.sys
    iastorv.sys
    ViPrt.sys
    eNetHook.dll
    ahcix86.sys
    KR10N.sys
    nvstor32.sys
    ahcix86s.sys
    nvrd32.sys
    symmpi.sys
    adp3132.sys
    /md5stop
    %systemroot%\*. /mp /s
    %systemroot%\system32\*.dll /lockedfiles
    %systemroot%\Tasks\*.job /lockedfiles
    %systemroot%\system32\drivers\*.sys /lockedfiles
    %systemroot%\System32\config\*.sav
    CREATERESTOREPOINT

  • Click the Quick Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post them in your next reply.


NEXT


Download GMER Rootkit Scanner from here to your desktop.
  • Double click the exe file. If asked to allow gmer.sys driver to load, please consent .
  • If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO.


    [external image: Posted Image]
    Click the image to enlarge it


  • In the right panel, you will see several boxes that have been checked. Uncheck the following …
    • Sections
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one)
  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop, and post it in reply.

**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries
Hello CatByte, thank you for your reply. I will be able to provide you with the OTL results. However, I tried running the GMER rootkit scanner, as per your specs, twice and twice it crashed and rebooted. I truly appreciate your time and effort.

Here are the OTL Results:

OTL logfile created on: 3/3/2010 4:52:20 PM - Run 1
OTL by OldTimer - Version 3.1.32.0 Folder = C:\Documents and Settings\Ortiz Family\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 60.00% Memory free
2.00 Gb Paging File | 1.00 Gb Available in Paging File | 75.00% Paging File free
Paging file location(s): [Binary data over 100 bytes]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 76.68 Gb Total Space | 62.41 Gb Free Space | 81.39% Space Free | Partition Type: NTFS
Drive D: | 93.34 Gb Total Space | 28.50 Gb Free Space | 30.53% Space Free | Partition Type: FAT32
E: Drive not present or media not loaded
F: Drive not present or media not loaded
Drive G: | 232.88 Gb Total Space | 21.35 Gb Free Space | 9.17% Space Free | Partition Type: NTFS
Drive H: | 149.05 Gb Total Space | 148.60 Gb Free Space | 99.70% Space Free | Partition Type: NTFS
I: Drive not present or media not loaded

Computer Name: JULIO
Current User Name: Ortiz Family
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: On
Skip Microsoft Files: On
File Age = 14 Days
Output = Minimal
Quick Scan

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\Ortiz Family\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\AVG\AVG9\avgtray.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG9\avgrsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG9\avgnsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG9\avgchsvx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG9\avgcsrvx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG9\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\Common Files\Teleca Shared\Generic.exe (Teleca AB)
PRC - C:\Program Files\HTC\HTC Sync\ClientInitiatedStarter\ClientInitiatedStarter.exe (Teleca)
PRC - C:\Program Files\HTC\HTC Sync\Mobile Phone Monitor\dbgout.exe (Teleca Sweden AB)
PRC - C:\Program Files\HTC\HTC Sync\Mobile Phone Monitor\epmworker.exe (Teleca Sweden AB)
PRC - C:\Program Files\HTC\HTC Sync\Mobile Phone Monitor\FsynSrvStarter.exe (TODO: )
PRC - C:\Program Files\HTC\HTC Sync\Mobile Phone Monitor\HTCVBTServer.exe (Teleca AB)
PRC - C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
PRC - C:\Program Files\Common Files\Teleca Shared\logger.exe (Popwire AB)
PRC - C:\Program Files\Common Files\Teleca Shared\CapabilityManager.exe (Teleca Sweden AB)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\ahead\InCD\incdsrv.exe (AHEAD Software)
PRC - C:\WINDOWS\system32\zstatus.exe (Zenographics)


========== Modules (SafeList) ==========

MOD - C:\Documents and Settings\Ortiz Family\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\WINDOWS\AppPatch\aclayers.dll (Microsoft Corporation)
MOD - C:\WINDOWS\system32\shimeng.dll (Microsoft Corporation)


========== Win32 Services (SafeList) ==========

SRV - (avg9wd) – C:\Program Files\AVG\AVG9\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
SRV - (InCDsrv) – C:\Program Files\ahead\InCD\incdsrv.exe (AHEAD Software)
SRV - (ATI Smart) – C:\WINDOWS\system32\ati2sgag.exe ()


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========


IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.msn.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = www.bing.com [binary data]
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchDefaultBranded = 1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.msn.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0



O1 HOSTS File: ([2010/04/03 00:56:35 | 000,377,755 | R— | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: 127.0.0.1 www.007guard.com
O1 - Hosts: 127.0.0.1 007guard.com
O1 - Hosts: 127.0.0.1 008i.com
O1 - Hosts: 127.0.0.1 www.008k.com
O1 - Hosts: 127.0.0.1 008k.com
O1 - Hosts: 127.0.0.1 www.00hq.com
O1 - Hosts: 127.0.0.1 00hq.com
O1 - Hosts: 127.0.0.1 010402.com
O1 - Hosts: 127.0.0.1 www.032439.com
O1 - Hosts: 127.0.0.1 032439.com
O1 - Hosts: 127.0.0.1 www.0scan.com
O1 - Hosts: 127.0.0.1 0scan.com
O1 - Hosts: 127.0.0.1 1000gratisproben.com
O1 - Hosts: 127.0.0.1 www.1000gratisproben.com
O1 - Hosts: 127.0.0.1 1001namen.com
O1 - Hosts: 127.0.0.1 www.1001namen.com
O1 - Hosts: 127.0.0.1 100888290cs.com
O1 - Hosts: 127.0.0.1 www.100888290cs.com
O1 - Hosts: 127.0.0.1 www.100sexlinks.com
O1 - Hosts: 127.0.0.1 100sexlinks.com
O1 - Hosts: 127.0.0.1 10sek.com
O1 - Hosts: 127.0.0.1 www.10sek.com
O1 - Hosts: 127.0.0.1 www.1-2005-search.com
O1 - Hosts: 127.0.0.1 1-2005-search.com
O1 - Hosts: 13022 more lines…
O2 - BHO: (Adobe PDF Link Helper) - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG9\avgssie.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll (Google Inc.)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.4.4525.1752\swg.dll (Google Inc.)
O2 - BHO: (Google Dictionary Compression sdch) - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll (Google Inc.)
O2 - BHO: (MSN Toolbar Helper) - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files\MSN\Toolbar\3.0.1203.0\msneshellx.dll (Microsoft Corp.)
O2 - BHO: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask.com)
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (JQSIEStartDetectorImpl Class) - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll (Sun Microsystems, Inc.)
O3 - HKLM\..\Toolbar: (MSN Toolbar) - {1E61ED7C-7CB8-49d6-B9E9-AB4C880C8414} - C:\Program Files\MSN\Toolbar\3.0.1203.0\msneshellx.dll (Microsoft Corp.)
O3 - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask.com)
O3 - HKCU\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll (Google Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask.com)
O4 - HKLM..\Run: [Adobe ARM] C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [Adobe Reader Speed Launcher] C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [AVG9_TRAY] C:\Program Files\AVG\AVG9\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [Mobile Connectivity Suite] C:\Program Files\HTC\HTC Sync\Application Launcher\Application Launcher.exe (Teleca Sweden AB)
O4 - HKCU..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
O4 - HKCU..\RunOnce: [UniblueRegistryBooster] C:\Program Files\Uniblue\RegistryBooster\launcher.exe File not found
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE (Microsoft Corporation)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8 - Extra context menu item: Add to Google Photos Screensa&ver; - C:\WINDOWS\System32\GPhotos.scr (Google Inc.)
O16 - DPF: {02BCC737-B171-4746-94C9-0D8A0B2C0089} http://office.microsoft.com/templates/ieawsdc.cab (Microsoft Office Template and Media Control)
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} http://cdn.scan.onecare.live.com/resource/…lscbase8942.cab (Windows Live Safety Center Base Module)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://update.microsoft.com/microsoftupdat…b?1246562226531 (MUWebControl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_15)
O16 - DPF: {CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_15)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_15)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed]
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG9\avgpp.dll (AVG Technologies CZ, s.r.o.)
O18 - Protocol\Filter\x-sdch {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll (Google Inc.)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\avgrsstarter: DllName - avgrsstx.dll - C:\WINDOWS\System32\avgrsstx.dll (AVG Technologies CZ, s.r.o.)
O24 - Desktop WallPaper: C:\WINDOWS\Web\Wallpaper\Bliss.bmp
O24 - Desktop BackupWallPaper: C:\WINDOWS\Web\Wallpaper\Bliss.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/07/01 22:42:12 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - comfile [open] – "%1" %*
O35 - exefile [open] – "%1" %*

NetSvcs: 6to4 - File not found
NetSvcs: Ias - C:\WINDOWS\system32\ias [2009/07/01 15:39:17 | 000,000,000 | —D | M]
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: Wmi - C:\WINDOWS\system32\wmi.dll (Microsoft Corporation)
NetSvcs: WmdmPmSp - File not found

CREATERESTOREPOINT
Restore point Set: OTL Restore Point (56016913389584384)

========== Files/Folders - Created Within 14 Days ==========

[2010/04/03 09:09:06 | 000,038,224 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2010/04/03 09:09:01 | 000,019,160 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2010/04/03 09:09:01 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware
[2010/04/03 05:54:25 | 000,000,000 | —D | M] – C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft
[2010/04/03 05:54:25 | 000,000,000 | —D | M] – C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft
[2010/04/03 05:54:24 | 000,000,000 | –SD | M] – C:\Documents and Settings\NetworkService\Application Data\Microsoft
[2010/04/03 05:54:24 | 000,000,000 | –SD | M] – C:\Documents and Settings\LocalService\Application Data\Microsoft
[2010/04/03 01:02:13 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Apple
[2010/04/03 01:01:51 | 000,000,000 | —D | C] – C:\Documents and Settings\Ortiz Family\Local Settings\Application Data\Apple
[2010/04/03 01:01:47 | 000,000,000 | —D | C] – C:\Program Files\Apple Software Update
[2010/04/03 01:01:47 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Apple
[2010/04/03 01:01:24 | 000,000,000 | —D | C] – C:\Documents and Settings\Ortiz Family\Local Settings\Application Data\Apple Computer
[2010/04/03 01:00:52 | 000,000,000 | —D | C] – C:\Program Files\Quicktime
[2010/04/02 23:53:51 | 000,000,000 | —D | C] – C:\Documents and Settings\Ortiz Family\My Documents\Updater
[2010/04/02 22:53:18 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Documents\Adobe PDF
[2010/04/02 22:49:12 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Adobe Systems
[2010/03/03 16:49:50 | 000,551,424 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Ortiz Family\Desktop\OTL.exe
[2010/03/03 16:24:51 | 000,000,000 | —D | C] – C:\Documents and Settings\Ortiz Family\Local Settings\Application Data\HTC
[2010/03/03 16:24:50 | 000,000,000 | —D | C] – C:\Documents and Settings\Ortiz Family\Application Data\Teleca
[2010/03/03 16:23:51 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\HTC
[2010/03/03 16:23:44 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Teleca Shared
[2010/03/03 16:23:44 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Teleca
[2010/03/03 16:22:10 | 000,000,000 | —D | C] – C:\WINDOWS\LastGood
[2010/03/03 16:22:09 | 000,025,728 | —- | C] (HTC1124 Inc) – C:\WINDOWS\System32\drivers\ANDROIDUSB.sys
[2010/03/03 16:21:48 | 000,000,000 | —D | C] – C:\Program Files\HTC
[2010/03/03 16:18:04 | 000,000,000 | —D | C] – C:\WINDOWS\Downloaded Installations
[2010/03/02 11:00:55 | 000,000,000 | —D | C] – C:\Documents and Settings\Ortiz Family\Application Data\Uniblue
[2010/03/02 11:00:48 | 000,000,000 | —D | C] – C:\Program Files\Uniblue
[2009/10/18 23:41:26 | 000,472,064 | —- | C] ( ) – C:\Program Files\RootRepeal.exe
[2009/10/18 23:39:31 | 000,050,688 | —- | C] (Atribune.org) – C:\Program Files\ATF_Cleaner.exe
[2009/10/18 23:32:48 | 004,045,528 | —- | C] (Malwarebytes Corporation ) – C:\Program Files\mbam-setup.exe
[2009/10/18 21:02:29 | 004,165,792 | —- | C] (Sammsoft ) – C:\Program Files\AROTrial_mt.exe
[2009/08/28 09:15:37 | 000,000,000 | —D | M] – C:\Documents and Settings\LocalService\Local Settings\Application Data\Help
[2009/08/28 09:15:37 | 000,000,000 | —D | M] – C:\Documents and Settings\LocalService\Application Data\Help
[5 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[2 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files - Modified Within 14 Days ==========

[2010/04/03 09:09:09 | 000,000,546 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/04/03 05:57:57 | 000,142,495 | —- | M] () – C:\WINDOWS\System32\drivers\Avg\microavi.avg
[2010/04/03 01:06:14 | 000,138,848 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2010/04/03 01:05:17 | 000,022,392 | —- | M] () – C:\Documents and Settings\Ortiz Family\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
[2010/04/03 01:01:52 | 000,000,284 | —- | M] () – C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2010/04/03 00:56:35 | 000,377,755 | R— | M] () – C:\WINDOWS\System32\drivers\etc\hosts
[2010/04/02 22:09:23 | 000,944,797 | —- | M] () – C:\Documents and Settings\Ortiz Family\Desktop\wrar.exe
[2010/03/03 16:50:24 | 008,126,464 | -H– | M] () – C:\Documents and Settings\Ortiz Family\NTUSER.DAT
[2010/03/03 16:50:04 | 000,551,424 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Ortiz Family\Desktop\OTL.exe
[2010/03/03 16:33:05 | 000,000,000 | -H– | M] () – C:\WINDOWS\System32\drivers\Msft_Kernel_ANDROIDUSB_01007.Wdf
[2010/03/03 16:33:04 | 000,000,000 | -H– | M] () – C:\WINDOWS\System32\drivers\MsftWdf_Kernel_01007_Coinstaller_Critical.Wdf
[2010/03/03 16:01:00 | 000,000,248 | —- | M] () – C:\WINDOWS\tasks\Scheduled Update for Ask Toolbar.job
[2010/03/03 05:07:38 | 056,595,798 | —- | M] () – C:\WINDOWS\System32\drivers\Avg\incavi.avm
[2010/03/01 08:37:08 | 000,376,874 | —- | M] () – C:\Documents and Settings\Ortiz Family\Desktop\Course+Syllabus+303.wpd
[2010/02/28 04:47:00 | 000,000,456 | —- | M] () – C:\WINDOWS\tasks\Driver Robot.job
[2010/02/27 12:49:12 | 000,000,432 | —- | M] () – C:\WINDOWS\System32\drivers\etc\hosts.ics
[2010/02/27 12:48:43 | 000,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2010/02/27 12:48:34 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2010/02/27 12:25:08 | 000,013,646 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2010/02/26 19:54:44 | 000,025,088 | —- | M] () – C:\Documents and Settings\Ortiz Family\Desktop\I love you Dad.doc
[2010/02/26 17:07:11 | 000,024,064 | —- | M] () – C:\Documents and Settings\Ortiz Family\Desktop\Raymond Robert Davis.doc
[2010/02/24 03:16:47 | 000,000,178 | -HS- | M] () – C:\Documents and Settings\Ortiz Family\ntuser.ini
[2010/02/24 03:01:26 | 000,001,374 | —- | M] () – C:\WINDOWS\imsins.BAK
[2010/02/23 16:37:34 | 000,000,658 | —- | M] () – C:\WINDOWS\win.ini
[2010/02/23 16:37:34 | 000,000,299 | —- | M] () – C:\WINDOWS\system.ini
[2010/02/23 06:20:06 | 000,058,880 | —- | M] () – C:\Documents and Settings\Ortiz Family\Desktop\Bobbi Jo Ortiz 2009_2010 Monthly Matrices(1).xls
[5 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[2 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files Created - No Company Name ==========

[2010/04/03 09:09:09 | 000,000,546 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/04/03 01:01:52 | 000,000,284 | —- | C] () – C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2010/04/02 22:09:10 | 000,944,797 | —- | C] () – C:\Documents and Settings\Ortiz Family\Desktop\wrar.exe
[2010/03/03 16:33:05 | 000,000,000 | -H– | C] () – C:\WINDOWS\System32\drivers\Msft_Kernel_ANDROIDUSB_01007.Wdf
[2010/03/03 16:33:04 | 000,000,000 | -H– | C] () – C:\WINDOWS\System32\drivers\MsftWdf_Kernel_01007_Coinstaller_Critical.Wdf
[2010/03/01 08:37:06 | 000,376,874 | —- | C] () – C:\Documents and Settings\Ortiz Family\Desktop\Course+Syllabus+303.wpd
[2010/02/26 18:02:53 | 000,025,088 | —- | C] () – C:\Documents and Settings\Ortiz Family\Desktop\I love you Dad.doc
[2010/02/26 16:39:40 | 000,024,064 | —- | C] () – C:\Documents and Settings\Ortiz Family\Desktop\Raymond Robert Davis.doc
[2010/01/04 17:20:52 | 000,087,040 | —- | C] () – C:\WINDOWS\System32\drivers\incdfs.sys
[2009/08/04 08:58:42 | 000,802,603 | —- | C] () – C:\WINDOWS\System32\ff_x264.dll
[2009/08/04 08:57:44 | 000,557,003 | —- | C] () – C:\WINDOWS\System32\libmplayer.dll
[2009/08/04 06:07:10 | 004,455,179 | —- | C] () – C:\WINDOWS\System32\libavcodec.dll
[2009/07/29 16:10:42 | 000,829,781 | —- | C] () – C:\WINDOWS\System32\xvidcore.dll
[2009/07/14 06:19:40 | 000,425,040 | —- | C] () – C:\WINDOWS\System32\TomsMoComp_ff.dll
[2009/07/14 05:31:04 | 000,146,098 | —- | C] () – C:\WINDOWS\System32\libmpeg2_ff.dll
[2009/07/13 08:54:26 | 000,008,192 | —- | C] () – C:\Documents and Settings\Ortiz Family\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/07/03 14:40:15 | 000,049,152 | —- | C] () – C:\WINDOWS\System32\VZWDLManager.dll
[2009/07/03 08:38:36 | 000,045,056 | —- | C] () – C:\WINDOWS\System32\vusetup.dll
[2009/07/03 08:25:28 | 000,233,525 | —- | C] () – C:\WINDOWS\System32\isutil.dll
[2009/07/03 08:25:26 | 000,000,271 | —- | C] () – C:\WINDOWS\apptune.ini
[2009/07/03 07:28:25 | 000,019,968 | —- | C] () – C:\WINDOWS\System32\cpuinf32.dll
[2009/07/03 07:26:31 | 000,000,138 | —- | C] () – C:\WINDOWS\wininit.ini
[2009/07/02 23:59:01 | 000,003,000 | R— | C] () – C:\WINDOWS\System32\SetupNT.sys
[2009/07/02 23:49:12 | 000,000,376 | —- | C] () – C:\WINDOWS\ODBC.INI
[2009/07/02 04:19:02 | 000,755,200 | —- | C] () – C:\WINDOWS\System32\ir50_32.dll
[2009/07/02 04:19:02 | 000,338,432 | —- | C] () – C:\WINDOWS\System32\ir41_qcx.dll
[2009/07/02 04:19:02 | 000,200,192 | —- | C] () – C:\WINDOWS\System32\ir50_qc.dll
[2009/07/02 04:19:02 | 000,183,808 | —- | C] () – C:\WINDOWS\System32\ir50_qcx.dll
[2009/07/02 04:19:02 | 000,120,320 | —- | C] () – C:\WINDOWS\System32\ir41_qc.dll
[2009/07/01 22:57:36 | 000,086,648 | —- | C] () – C:\WINDOWS\System32\drivers\US122Wdm.sys
[2009/07/01 22:57:17 | 000,213,196 | —- | C] () – C:\WINDOWS\System32\drivers\US122.sys
[2009/07/01 22:57:17 | 000,017,277 | —- | C] () – C:\WINDOWS\System32\drivers\US122DL.sys
[2009/06/02 10:35:00 | 000,328,334 | —- | C] () – C:\WINDOWS\System32\ff_kernelDeint.dll
[2009/06/02 10:15:44 | 000,113,152 | —- | C] () – C:\WINDOWS\System32\ff_unrar.dll
[2009/06/02 10:15:18 | 000,146,944 | —- | C] () – C:\WINDOWS\System32\ff_tremor.dll
[2009/06/02 10:15:04 | 000,183,296 | —- | C] () – C:\WINDOWS\System32\ff_samplerate.dll
[2009/06/02 10:14:56 | 000,178,688 | —- | C] () – C:\WINDOWS\System32\ff_libmad.dll
[2009/06/02 10:14:30 | 000,486,400 | —- | C] () – C:\WINDOWS\System32\ff_libfaad2.dll
[2009/06/02 10:13:58 | 000,257,024 | —- | C] () – C:\WINDOWS\System32\ff_libdts.dll
[2009/06/02 10:13:50 | 000,142,848 | —- | C] () – C:\WINDOWS\System32\ff_liba52.dll
[2009/06/02 10:11:26 | 000,098,304 | —- | C] () – C:\WINDOWS\System32\ff_wmv9.dll
[2009/06/02 10:11:16 | 000,085,504 | —- | C] () – C:\WINDOWS\System32\ff_vfw.dll
[2009/01/10 15:17:32 | 000,163,840 | —- | C] () – C:\WINDOWS\System32\ts.dll
[2009/01/10 15:16:56 | 000,148,480 | —- | C] () – C:\WINDOWS\System32\mkx.dll
[2009/01/10 15:16:50 | 000,108,032 | —- | C] () – C:\WINDOWS\System32\avi.dll
[2009/01/10 15:16:14 | 000,141,312 | —- | C] () – C:\WINDOWS\System32\mp4.dll
[2009/01/10 15:15:54 | 000,120,832 | —- | C] () – C:\WINDOWS\System32\ogm.dll
[2009/01/10 15:15:44 | 000,159,744 | —- | C] () – C:\WINDOWS\System32\mmfinfo.dll
[2009/01/10 15:15:32 | 000,102,400 | —- | C] () – C:\WINDOWS\System32\avss.dll
[2009/01/10 15:15:28 | 000,246,784 | —- | C] () – C:\WINDOWS\System32\dxr.dll
[2009/01/10 15:15:12 | 000,097,280 | —- | C] () – C:\WINDOWS\System32\avs.dll
[2009/01/10 15:14:08 | 000,079,360 | —- | C] () – C:\WINDOWS\System32\mkzlib.dll
[2009/01/10 15:14:06 | 000,023,552 | —- | C] () – C:\WINDOWS\System32\mkunicode.dll
[2008/12/03 15:11:50 | 000,180,224 | —- | C] () – C:\WINDOWS\System32\xvidvfw.dll
[2008/11/06 09:37:32 | 003,596,288 | —- | C] () – C:\WINDOWS\System32\qt-dx331.dll
[2008/11/06 09:34:00 | 000,000,416 | —- | C] () – C:\WINDOWS\System32\dtu100.dll.manifest
[2007/10/13 02:30:20 | 000,000,137 | —- | C] () – C:\WINDOWS\System32\Registration.ini
[2007/07/10 10:10:12 | 000,000,547 | —- | C] () – C:\WINDOWS\System32\ff_vfw.dll.manifest
[2003/06/02 19:31:38 | 000,090,112 | —- | C] () – C:\WINDOWS\System32\ati2evxx.dll
[2002/12/12 17:44:30 | 000,000,000 | —- | C] () – C:\WINDOWS\System32\px.ini
[2002/05/24 00:00:00 | 000,208,896 | —- | C] () – C:\WINDOWS\System32\lockout.dll
[2002/05/24 00:00:00 | 000,045,056 | —- | C] () – C:\WINDOWS\System32\lockres.dll
[2001/08/31 14:33:58 | 000,425,984 | —- | C] () – C:\WINDOWS\System32\VxDMDcDlg.dll
[2001/08/14 10:47:08 | 000,020,480 | —- | C] () – C:\WINDOWS\System32\vxpsapi.dll
[1999/01/22 19:46:58 | 000,065,536 | —- | C] () – C:\WINDOWS\System32\MSRTEDIT.DLL

========== LOP Check ==========

[2010/04/03 05:53:20 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\avg9
[2010/03/03 16:23:51 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\HTC
[2009/12/17 04:11:42 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\iZotope
[2009/07/10 15:31:51 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PopCap
[2010/03/03 16:23:47 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Teleca
[2009/12/17 04:33:36 | 000,000,000 | —D | M] – C:\Documents and Settings\Ortiz Family\Application Data\Antares
[2009/10/07 09:24:31 | 000,000,000 | —D | M] – C:\Documents and Settings\Ortiz Family\Application Data\AVCWare Studio
[2009/11/26 08:30:07 | 000,000,000 | —D | M] – C:\Documents and Settings\Ortiz Family\Application Data\Blitware
[2009/08/01 07:39:53 | 000,000,000 | —D | M] – C:\Documents and Settings\Ortiz Family\Application Data\com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
[2009/07/03 13:11:31 | 000,000,000 | —D | M] – C:\Documents and Settings\Ortiz Family\Application Data\Outertech
[2009/10/05 09:05:13 | 000,000,000 | —D | M] – C:\Documents and Settings\Ortiz Family\Application Data\Southwest Airlines
[2010/03/03 16:33:58 | 000,000,000 | —D | M] – C:\Documents and Settings\Ortiz Family\Application Data\Teleca
[2010/03/02 11:00:55 | 000,000,000 | —D | M] – C:\Documents and Settings\Ortiz Family\Application Data\Uniblue
[2010/04/02 23:25:43 | 000,000,000 | —D | M] – C:\Documents and Settings\Ortiz Family\Application Data\uTorrent
[2009/07/03 12:07:27 | 000,000,000 | —D | M] – C:\Documents and Settings\Ortiz Family\Application Data\VERITAS
[2010/02/28 04:47:00 | 000,000,456 | —- | M] () – C:\WINDOWS\Tasks\Driver Robot.job
[2010/03/03 16:01:00 | 000,000,248 | —- | M] () – C:\WINDOWS\Tasks\Scheduled Update for Ask Toolbar.job

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.exe >


< MD5 for: AGP440.SYS >
[2004/08/04 00:05:44 | 018,738,937 | —- | M] () .cab file – C:\WINDOWS\Driver Cache\i386\sp2.cab:AGP440.sys
[2009/07/10 09:34:18 | 023,852,652 | —- | M] () .cab file – C:\WINDOWS\Driver Cache\i386\sp3.cab:AGP440.sys
[2004/08/04 00:05:44 | 018,738,937 | —- | M] () .cab file – C:\WINDOWS\ServicePackFiles\i386\sp2.cab:AGP440.sys
[2009/07/10 09:34:18 | 023,852,652 | —- | M] () .cab file – C:\WINDOWS\ServicePackFiles\i386\sp3.cab:AGP440.sys
[2008/04/13 11:36:38 | 000,042,368 | —- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 – C:\WINDOWS\ServicePackFiles\i386\agp440.sys
[2008/04/13 11:36:38 | 000,042,368 | —- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 – C:\WINDOWS\system32\drivers\agp440.sys
[2004/08/03 22:07:42 | 000,042,368 | —- | M] (Microsoft Corporation) MD5=2C428FA0C3E3A01ED93C9B2A27D8D4BB – C:\WINDOWS\$NtServicePackUninstall$\agp440.sys

< MD5 for: ATAPI.SYS >
[2003/03/31 05:00:00 | 010,158,890 | —- | M] () .cab file – C:\WINDOWS\Driver Cache\i386\sp1.cab:atapi.sys
[2004/08/04 00:05:44 | 018,738,937 | —- | M] () .cab file – C:\WINDOWS\Driver Cache\i386\sp2.cab:atapi.sys
[2009/07/10 09:34:18 | 023,852,652 | —- | M] () .cab file – C:\WINDOWS\Driver Cache\i386\sp3.cab:atapi.sys
[2004/08/04 00:05:44 | 018,738,937 | —- | M] () .cab file – C:\WINDOWS\ServicePackFiles\i386\sp2.cab:atapi.sys
[2009/07/10 09:34:18 | 023,852,652 | —- | M] () .cab file – C:\WINDOWS\ServicePackFiles\i386\sp3.cab:atapi.sys
[2008/04/13 11:40:30 | 000,096,512 | —- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 – C:\WINDOWS\ServicePackFiles\i386\atapi.sys
[2008/04/13 11:40:30 | 000,096,512 | —- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 – C:\WINDOWS\system32\drivers\atapi.sys
[2004/08/03 21:59:44 | 000,095,360 | —- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 – C:\WINDOWS\$NtServicePackUninstall$\atapi.sys

< MD5 for: EVENTLOG.DLL >
[2008/04/13 17:11:53 | 000,056,320 | —- | M] (Microsoft Corporation) MD5=6D4FEB43EE538FC5428CC7F0565AA656 – C:\WINDOWS\ServicePackFiles\i386\eventlog.dll
[2008/04/13 17:11:53 | 000,056,320 | —- | M] (Microsoft Corporation) MD5=6D4FEB43EE538FC5428CC7F0565AA656 – C:\WINDOWS\system32\eventlog.dll
[2004/08/03 23:56:44 | 000,055,808 | —- | M] (Microsoft Corporation) MD5=82B24CB70E5944E6E34662205A2A5B78 – C:\WINDOWS\$NtServicePackUninstall$\eventlog.dll

< MD5 for: NETLOGON.DLL >
[2008/04/13 17:12:01 | 000,407,040 | —- | M] (Microsoft Corporation) MD5=1B7F071C51B77C272875C3A23E1E4550 – C:\WINDOWS\ServicePackFiles\i386\netlogon.dll
[2008/04/13 17:12:01 | 000,407,040 | —- | M] (Microsoft Corporation) MD5=1B7F071C51B77C272875C3A23E1E4550 – C:\WINDOWS\system32\netlogon.dll
[2004/08/03 23:56:46 | 000,407,040 | —- | M] (Microsoft Corporation) MD5=96353FCECBA774BB8DA74A1C6507015A – C:\WINDOWS\$NtServicePackUninstall$\netlogon.dll

< MD5 for: SCECLI.DLL >
[2004/08/03 23:56:46 | 000,180,224 | —- | M] (Microsoft Corporation) MD5=0F78E27F563F2AAF74B91A49E2ABF19A – C:\WINDOWS\$NtServicePackUninstall$\scecli.dll
[2008/04/13 17:12:05 | 000,181,248 | —- | M] (Microsoft Corporation) MD5=A86BB5E61BF3E39B62AB4C7E7085A084 – C:\WINDOWS\ServicePackFiles\i386\scecli.dll
[2008/04/13 17:12:05 | 000,181,248 | —- | M] (Microsoft Corporation) MD5=A86BB5E61BF3E39B62AB4C7E7085A084 – C:\WINDOWS\system32\scecli.dll

< %systemroot%\*. /mp /s >

< %systemroot%\system32\*.dll /lockedfiles >
[2009/03/08 03:31:44 | 000,348,160 | —- | M] (Microsoft Corporation) Unable to obtain MD5 – C:\WINDOWS\system32\dxtmsft.dll
[2009/03/08 03:31:38 | 000,216,064 | —- | M] (Microsoft Corporation) Unable to obtain MD5 – C:\WINDOWS\system32\dxtrans.dll
[2 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]

< %systemroot%\Tasks\*.job /lockedfiles >

< %systemroot%\system32\drivers\*.sys /lockedfiles >

< %systemroot%\System32\config\*.sav >
[2009/07/01 15:41:54 | 000,094,208 | —- | M] () – C:\WINDOWS\system32\config\default.sav
[2009/07/01 15:41:54 | 000,602,112 | —- | M] () – C:\WINDOWS\system32\config\software.sav
[2009/07/01 15:41:54 | 000,417,792 | —- | M] () – C:\WINDOWS\system32\config\system.sav
< End of report >


& HERE IS I EXTRAS

OTL Extras logfile created on: 3/3/2010 4:52:20 PM - Run 1
OTL by OldTimer - Version 3.1.32.0 Folder = C:\Documents and Settings\Ortiz Family\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 60.00% Memory free
2.00 Gb Paging File | 1.00 Gb Available in Paging File | 75.00% Paging File free
Paging file location(s): [Binary data over 100 bytes]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 76.68 Gb Total Space | 62.41 Gb Free Space | 81.39% Space Free | Partition Type: NTFS
Drive D: | 93.34 Gb Total Space | 28.50 Gb Free Space | 30.53% Space Free | Partition Type: FAT32
E: Drive not present or media not loaded
F: Drive not present or media not loaded
Drive G: | 232.88 Gb Total Space | 21.35 Gb Free Space | 9.17% Space Free | Partition Type: NTFS
Drive H: | 149.05 Gb Total Space | 148.60 Gb Free Space | 99.70% Space Free | Partition Type: NTFS
I: Drive not present or media not loaded

Computer Name: JULIO
Current User Name: Ortiz Family
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: On
Skip Microsoft Files: On
File Age = 14 Days
Output = Minimal
Quick Scan

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.ini [@ = GetDiz.Document] – C:\Program Files\GetDiz\GetDiz.exe (Outertech - http://outertech.com)
.txt [@ = GetDiz.Document] – C:\Program Files\GetDiz\GetDiz.exe (Outertech - http://outertech.com)

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
exefile [open] – "%1" %*
htmlfile – "C:\Program Files\Microsoft Office\Office\msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [print] – "C:\Program Files\Microsoft Office\Office\msohtmed.exe" /p %1 (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] – "%1" %*
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 1
"FirewallOverride" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
"139:TCP" = 139:TCP:*:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:*:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:*:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:*:Enabled:@xpsp2res.dll,-22002

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
"DoNotAllowExceptions" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"139:TCP" = 139:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22002
"3389:TCP" = 3389:TCP:*:Enabled:@xpsp2res.dll,-22009

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\AVG\AVG9\avgupd.exe" = C:\Program Files\AVG\AVG9\avgupd.exe:*:Enabled:avgupd.exe – (AVG Technologies CZ, s.r.o.)
"C:\Program Files\AVG\AVG9\avgnsx.exe" = C:\Program Files\AVG\AVG9\avgnsx.exe:*:Enabled:avgnsx.exe – (AVG Technologies CZ, s.r.o.)
"C:\Program Files\utorrent\utorrent.exe" = C:\Program Files\utorrent\utorrent.exe:*:Enabled:µTorrent – (BitTorrent, Inc.)


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{00000409-78E1-11D2-B60F-006097C998E7}" = Microsoft Office 2000 Premium
"{0BEDBD4E-2D34-47B5-9973-57E62B29307C}" = ATI Control Panel
"{0DFB3DE8-65B9-44FF-AA0A-3BECC5A2BFD1}" = Adobe Flash Player 10 Plugin
"{18455581-E099-4BA8-BC6B-F34B2F06600C}" = Google Toolbar for Internet Explorer
"{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer
"{236BB7C4-4419-42FD-0409-1E257A25E34D}" = Adobe Photoshop CS2
"{26A24AE4-039D-4CA4-87B4-2F83216015FF}" = Java™ 6 Update 15
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{3560CE5A-C4EF-4DB0-9ECC-BA035FE309C5}" = MSN Toolbar
"{3EA9D975-BFDC-4E8E-B88B-0446FBC8CA66}" = ATI HydraVision
"{3FA365DF-2D68-45ED-8F83-8C8A33E65143}" = Apple Application Support
"{60E80B13-8649-4A69-85E2-1AE99E061F43}" = ShowBiz DVD
"{60E971B7-51A0-48CA-8687-C6B8F094A409}" = Simple Backup
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{6D6664A9-3342-4948-9B7E-034EFE366F0F}" = HTC Driver
"{6D8D64BE-F500-55B6-705D-DFD08AFE0624}" = Acrobat.com
"{786C5747-1033-0000-B58E-000000000001}" = Adobe Stock Photos 1.0
"{8214CC02-6271-4DC8-B8DD-779933450264}" = RecordNow
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{84031A18-BA9A-4156-A74F-E05B52DDFCE2}" = DING!
"{86D4B82A-ABED-442A-BE86-96357B70F4FE}" = Ask Toolbar
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8EDBA74D-0686-4C99-BFDD-F894678E5B39}" = Adobe Common File Installer
"{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system
"{90850409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Word Viewer 2003
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{975C8028-51D8-44A9-9585-82E9810FE96A}" = hp LaserJet 1000
"{A2BCA9F1-566C-4805-97D1-7FDC93386723}" = Adobe AIR
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A4D7B764-4140-11D4-88EB-0050DA3579C0}" = Nero - Burning Rom
"{AC76BA86-7AD7-1033-7B44-A93000000001}" = Adobe Reader 9.3
"{B74D4E10-1033-0000-0000-000000000001}" = Adobe Bridge 1.0
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C3ABE126-2BB2-4246-BFE1-6797679B3579}" = LG USB Modem driver
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D5AF36E3-D72D-4E30-AB64-48A98BDDEE73}" = HTC Sync
"{E9787678-1033-0000-8E67-000000000001}" = Adobe Help Center 1.0
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Photoshop CS2 - {236BB7C4-4419-42FD-0409-1E257A25E34D}" = Adobe Photoshop CS2
"Antares AutoTune v3.08" = Antares AutoTune v3.08
"Antares Autotune VST_is1" = Antares Autotune VST v5.09
"Antares AVOX Vocal Kit Bundle VST v1.02" = Antares AVOX Vocal Kit Bundle VST v1.02
"Antares Microphone Modeler - ZONE" = Antares Microphone Modeler - ZONE
"ATI Display Driver" = ATI Display Driver
"AVG9Uninstall" = AVG Free 9.0
"Cool Edit Pro 2.1" = Cool Edit Pro 2.1
"Coupon Printer for Windows5.0.0.0" = Coupon Printer for Windows
"Effectrix" = Effectrix
"GetDiz 4.5" = GetDiz 4.5
"HijackThis" = HijackThis 2.0.2
"hp dvd writer" = hp dvd writer
"ie8" = Windows Internet Explorer 8
"InCD!UninstallKey" = Ahead InCD
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Media Player - Codec Pack" = Media Player Codec Pack 3.7.0
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"MRW!UninstallKey" = Ahead InCD EasyWrite Reader
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"NMPUninstallKey" = Ahead NeroMediaPlayer
"Picasa 3" = Picasa 3
"US-122" = US-122
"uTorrent" = µTorrent
"VCast Music Essentials Manager" = V CAST Music Manager
"Veetle TV" = Veetle TV 0.9.15
"Waves Audio Processors" = Waves Audio Processors
"Waves Diamond Bundle v5.0" = Waves Diamond Bundle v5.0
"Waves Gold Processors 3.5" = Waves Gold Processors 3.5
"Waves L3 Multimaximizer v1.0" = Waves L3 Multimaximizer v1.0
"Wdf01007" = Microsoft Kernel-Mode Driver Framework Feature Pack 1.7
"Windows Live OneCare safety scanner" = Windows Live OneCare safety scanner
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"Windows XP Service Pack" = Windows XP Service Pack 3
"WinRAR archiver" = WinRAR archiver
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 2/7/2010 9:44:45 AM | Computer Name = JULIO | Source = Application Hang | ID = 1002
Description = Hanging application iexplore.exe, version 8.0.6001.18702, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.

Error - 2/10/2010 1:15:54 PM | Computer Name = JULIO | Source = Application Error | ID = 1000
Description = Faulting application coolpro2.exe, version 2.1.3097.0, faulting module
coolpro2.exe, version 2.1.3097.0, fault address 0x00205dd5.

Error - 2/10/2010 1:34:25 PM | Computer Name = JULIO | Source = Application Error | ID = 1000
Description = Faulting application coolpro2.exe, version 2.1.3097.0, faulting module
coolpro2.exe, version 2.1.3097.0, fault address 0x0013fdbc.

Error - 2/11/2010 3:05:02 PM | Computer Name = JULIO | Source = Application Error | ID = 1000
Description = Faulting application coolpro2.exe, version 2.1.3097.0, faulting module
coolpro2.exe, version 2.1.3097.0, fault address 0x00207ad0.

Error - 2/11/2010 3:06:59 PM | Computer Name = JULIO | Source = Application Error | ID = 1000
Description = Faulting application coolpro2.exe, version 2.1.3097.0, faulting module
coolpro2.exe, version 2.1.3097.0, fault address 0x00207ad0.

Error - 2/11/2010 3:07:40 PM | Computer Name = JULIO | Source = Application Error | ID = 1000
Description = Faulting application coolpro2.exe, version 2.1.3097.0, faulting module
coolpro2.exe, version 2.1.3097.0, fault address 0x00207ad0.

Error - 2/12/2010 1:03:32 AM | Computer Name = JULIO | Source = Application Error | ID = 1000
Description = Faulting application coolpro2.exe, version 2.1.3097.0, faulting module
coolpro2.exe, version 2.1.3097.0, fault address 0x00207ad0.

Error - 2/12/2010 9:21:39 PM | Computer Name = JULIO | Source = Application Hang | ID = 1002
Description = Hanging application iexplore.exe, version 8.0.6001.18702, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.

Error - 2/16/2010 5:23:12 PM | Computer Name = JULIO | Source = Application Hang | ID = 1002
Description = Hanging application iexplore.exe, version 8.0.6001.18702, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.

Error - 2/24/2010 10:59:53 PM | Computer Name = JULIO | Source = Application Error | ID = 1000
Description = Faulting application winword.exe, version 9.0.0.2717, faulting module
winword.exe, version 9.0.0.2717, fault address 0x0040799d.

[ System Events ]
Error - 4/3/2010 4:07:07 AM | Computer Name = JULIO | Source = ipnathlp | ID = 30013
Description = The DHCP allocator has disabled itself on IP address [removed],
since
the IP address is outside the 192.168.0.0/255.255.255.0 scope from which addresses
are being allocated to DHCP clients. To enable the DHCP allocator on this IP address,
please
change the scope to include the IP address, or change the IP address to fall within
the scope.

Error - 4/3/2010 4:07:17 AM | Computer Name = JULIO | Source = W32Time | ID = 39452706
Description = The time service has detected that the system time needs to be changed
by -5180398 seconds. The time service will not change the system time by more than
-54000 seconds. Verify that your time and time zone are correct, and that the time
source time.windows.com (ntp.m|0x1|24.92.115.95:123->207.46.232.182:123) is working
properly.

Error - 4/3/2010 8:59:31 AM | Computer Name = JULIO | Source = W32Time | ID = 39452706
Description = The time service has detected that the system time needs to be changed
by -5180397 seconds. The time service will not change the system time by more than
-54000 seconds. Verify that your time and time zone are correct, and that the time
source time.windows.com (ntp.m|0x1|[removed]:123->207.46.232.182:123) is working
properly.


< End of report >
try running GMER in safe mode, uncheck the box beside "files" as well Make sure all your security programs are disabled and all other programs closed. Try and note any files GMER detects that are "rootkits", "suspicious modifications", "hidden" or say "max++"
ok . I performed scan in safe mode without sections, iat/eat, files, partitions other than system drive, show all. …it finally scraped through without crashing. I will await your instructions, greatly appreciated.

Juliusmaximus

gmer.txt:

GMER 1.0.15.15281 - http://www.gmer.net
Rootkit scan 2010-03-04 14:25:55
Windows 5.1.2600 Service Pack 3
Running: GMER rootkit scanner.exe; Driver: C:\DOCUME~1\ORTIZF~1\LOCALS~1\Temp\uxtdypod.sys


—- Devices - GMER 1.0.15 —-

Device \FileSystem\Cdfs \Cdfs BA777400

—- EOF - GMER 1.0.15 —-
Hi,

There are no obvious signs of malware in the logs, but lets do a couple of scans to be certain, there still could be a couple of infected files on board that may not be showing.


please do the following:
  • Please open your MalwareBytes AntiMalware Program
  • Click the Update Tab and search for updates
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish, so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected. <– very important
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart. (See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.

Extra Note:If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts, click OK to either and let MBAM proceed with the disinfection process, if asked to restart the computer, please do so immediately.




NEXT


Run an on-line scan with Kaspersky

Using Internet Explorer or Firefox, visit Kaspersky On-line Scanner

1. Click Accept, when prompted to download and install the program files and database of malware definitions.
2. To optimize scanning time and produce a more sensible report for review:
  • Close any open programs
  • Turn off the real time scanner of any existing antivirus program while performing the online scan
3. Click Run at the Security prompt.
The program will then begin downloading and installing and will also update the database.
Please be patient as this can take several minutes.
  • Once the update is complete, click on My Computer under the green Scan bar to the left to start the scan.
  • Once the scan is complete, it will display if your system has been infected. It does not provide an option to clean/disinfect. We only require a report from it.
  • Do NOT be alarmed by what you see in the report. Many of the finds have likely been quarantined.
  • Click View scan report at the bottom.

    [external image: Posted Image]
  • Click the Save as Text button to save the file to your desktop so that you may post it in your next reply


In your next reply please include
  • MBAM Log
  • Kaspersky report
Hey there cat, I ran the MBAM in safe mode and it came up clear, I've posted the log below. I was uable to succesfully run Kaspersky online scan, 3 attempts 3 system crashes, same as when I try to watch video in sull screen. Here is the MBAM LOG: Malwarebytes' Anti-Malware 1.44 Database version: 3826 Windows 5.1.2600 Service Pack 3 Internet Explorer 8.0.6001.18702 3/5/2010 10:33:18 AM mbam-log-2010-03-05 (10-33-18).txt Scan type: Quick Scan Objects scanned: 125227 Time elapsed: 8 minute(s), 39 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected)
Try this scanner instead




Go here to run an online scanner from ESET.

  • Note: You will need to use Internet explorer for this scan
  • Turn off the real time scanner of any existing antivirus program while performing the online scan
  • Tick the box next to YES, I accept the Terms of Use.
  • Click Start
  • When asked, allow the activeX control to install
  • Click Start
  • Make sure that the option Remove found threats is unticked and the Scan Archives option is ticked.
  • Click on Advanced Settings, ensure the options Scan for potentially unwanted applications, Scan for potentially unsafe applications, and Enable Anti-Stealth Technology are ticked.
  • Click Scan
  • Wait for the scan to finish
  • Use notepad to open the logfile located at C:\Program Files\Eset\Eset Online Scanner\log.txt
  • Copy and paste that log as a reply to this topic and also let me know how things are now.
Hello Cat, eSet ran succesfully, here are the results generated: ESETSmartInstaller@High as CAB hook log: OnlineScanner.ocx - registred OK # version=7 # iexplore.exe=8.00.6001.18702 (longhorn_ie8_rtm(wmbla).090308-0339) # OnlineScanner.ocx=1.0.0.6211 # api_version=3.0.2 # EOSSerial=aae685f3d2c8f64483d39d13e62dcc51 # end=finished # remove_checked=false # archives_checked=true # unwanted_checked=true # unsafe_checked=true # antistealth_checked=true # utc_time=2010-03-06 07:31:48 # local_time=2010-03-06 12:31:48 (-0700, Mountain Standard Time) # country="United States" # lang=1033 # osver=5.1.2600 NT Service Pack 3 # compatibility_mode=512 16777215 100 0 2597199 2597199 0 0 # compatibility_mode=1024 16777175 100 0 7661866 7661866 0 0 # compatibility_mode=8192 67108863 100 0 0 0 0 0 # scanned=150876 # found=10 # cleaned=0 # scan_time=27812 G:\!–GAMES\kids - Fisher Price Pet Shop - gizmo14.iso Win32/Adware.DSSAgent application 00000000000000000000000000000000 I G:\C drive Backup\My Documents\Julio\Adobe hax\midacskg.rar probably a variant of Win32/TrojanDownloader.Agent trojan 00000000000000000000000000000000 I G:\C drive Backup\Shared\2_Adobe Photoshop 8 CS Crack+Keygenerator.zip probably a variant of Win32/TrojanDownloader.Agent trojan 00000000000000000000000000000000 I G:\ISO'S\!PROGRAMS\Adobe Photoshop CS4\Adobe.Photoshop.CS4.Extended.Incl.[Retail].Patch-NoPE\Adobe.Photoshop.CS4.Extended.Incl.[Retail].Patch-NoPE.rar multiple threats 00000000000000000000000000000000 I G:\ISO'S\!PROGRAMS\PORTABLES 2009 MEGA PACK\Portables 2009.iso multiple threats 00000000000000000000000000000000 I G:\ISO'S\WINDOWS\02-02-2009-Vortex-3G\02-02-2009-Vortex-3G.iso multiple threats 00000000000000000000000000000000 I G:\Windows OneCare Backup\JULIO\2009\Files\Part 1150.ZIP probably a variant of Win32/TrojanDownloader.Agent trojan 00000000000000000000000000000000 I G:\Windows OneCare Backup\JULIO\2009\Files\Part 1336.ZIP probably a variant of Win32/TrojanDownloader.Agent trojan 00000000000000000000000000000000 I G:\Windows OneCare Backup\JULIO\2009\Files\Part 1366.ZIP multiple threats 00000000000000000000000000000000 I G:\Windows OneCare Backup\JULIO\2009\Files\Part 1367.ZIP VBS/Disabler.NAB trojan 00000000000000000000000000000000 I
Hi,

Please do the following:

  • Go to Start->Run and type in notepad and hit OK.
  • Then copy and paste the content of the following codebox into Notepad:

    @echo off 
    if exist "%temp%\log.txt" del "%temp%\log.txt"
    
    for %%g in ( 
    "G:\!–GAMES\kids - Fisher Price Pet Shop - gizmo14.iso"
    "G:\C drive Backup\My Documents\Julio\Adobe hax\midacskg.rar"
    "G:\C drive Backup\Shared\2_Adobe Photoshop 8 CS Crack+Keygenerator.zip"
    "G:\ISO'S\!PROGRAMS\Adobe Photoshop CS4\Adobe.Photoshop.CS4.Extended.Incl.[Retail].Patch-NoPE\Adobe.Photoshop.CS4.Extended.Incl.[Retail].Patch-NoPE.rar" 
    "G:\ISO'S\!PROGRAMS\PORTABLES 2009 MEGA PACK\Portables 2009.iso"
    "G:\ISO'S\WINDOWS\02-02-2009-Vortex-3G\02-02-2009-Vortex-3G.iso" 
    ) do (
    del /a/f/q %%g >nul 2>&1
    if exist %%g echo.%%g>>"%temp%\log.txt"
    )
    if exist "%temp%\log.txt" ( start notepad "%temp%\log.txt"
    ) else echo.Deleted Successfully !!
    pause
    del %0
  • Save the file to your DESKTOP as "find.bat". Make sure to save it with the quotes.
  • Once saved, the icon to click should look like this on your desktop:

    [external image: Posted Image]
  • Double click find.bat. to run it. A small black box should open and close - this is normal.
  • Let me know if it deletes successfully.



NEXT


Visit ADOBEand download the latest version of Acrobat Reader (version 9.3)
Having the latest updates ensures there are no security vulnerabilities in your system.


NEXT


[external image: Posted Image] Your Java is out of date.
Java™ 6 Update 15 can be updated from the Java control panel Start > Control Panel (Classic View) > Java (looks like a coffee cup) > Update Tab > Update Now.
An update should begin; > follow the prompts.



Please post a fresh OTL log and advise how the computer is running now and if there are any outstanding issues
alright cat, the "find.bat" said it deleted succesfully. I went to adobe to download new one, it downloaded the mcAfee that came with it but siad it could not download the adobe… I tried updating the Javas and system crashed twice. I tried updating Java in Safe Mode with Networking and it allowed me a b it further into Java options, when I finally hit install it replied, "System Administrator has set policies to prevent this installation."
tried running adobe reader update again, almost completed, then it said "a network error occured while attempting to read from file C:\Documents and Settings\Ortiz Family\\Local Settings\Application Data\Adobe\930_en_US.msi I should add that it gives me the option to Repair or Remove, i did repair everytime. I dont know if that helps any but…there it is. I will try the Java Update one more time.
Hi,

Let's take a deeper look, you shouldn't be having so much trouble with Java and Adobe.

Please do the following:

Download ComboFix from one of the following locations:
Link 1
Link 2

VERY IMPORTANT !!! Save ComboFix.exe to your Desktop

* IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here
  • Double click on ComboFix.exe & follow the prompts.
As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.
**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

[external image: Posted Image]

  • Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]

  • Click on Yes, to continue scanning for malware.
When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.
Notes:
1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.
Good news & bad news…. bad first…unable to perform combofix, downloaded fine but when i ran it is warned that AVG was still running even though I disabled it and rebooted (there is no "quit" feature in the systray lower right hand corner…only "open interface…couldnt find a durned off switch for it…went so far as trying to uninstall so as to run combofix, then reaqcuire AVG anew. While attempting to uninstall, it didnt let me, My brother in law installed this AVG on my computer awhile back, and I wasnt here to verify where he got what he got that day. here is the Good news…if it helps track the problem, the message and the log it offered as an error code and error log: Local machine: installation failed Installation: Error: Action failed for registry key HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows: creating registry key…. Access is denied And the attached was the log from the uninstall error. …..well never mind, it was 6.29 mb, wouldnt upload. So i cant run Combofix because I cant turn AVG - free version, off I tried couple of different approaches, but no luck. I once allowed a tech from Norton to "commandeer" my pc remotely, if that would speed things up, you are more than welcome to…just instruct me as what to do to facilitate that on my end.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI